context-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources including configuration rules and memory files which could potentially contain instructions aimed at influencing the agent's audit findings.\n
- Ingestion points: Project-level and global CLAUDE.md files, SKILL.md instruction files, and memory markdown files located in ~/.claude/projects/.\n
- Boundary markers: The instructions do not define specific delimiters or directives to ignore embedded instructions within these analyzed files.\n
- Capability inventory: The skill is permitted to read files across the project and home directory and can modify settings.json and other project configuration files.\n
- Sanitization: No sanitization or content validation is performed on the data ingested from the audited files.\n- [SAFE]: The skill performs legitimate configuration auditing for performance optimization. Access to settings.json and local project metadata is required for its diagnostic purpose.\n- [SAFE]: No network operations or external data exfiltration patterns were identified. All identified operations remain local to the user's environment, and modifications to primary instruction files require explicit user confirmation.
Audit Metadata